EJ3 TOPo 2.2.178 includes the password in cleartext in the ID field to index.php, which allows context-dependent attackers to obtain entry passwords via log files, referrers, or other vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Topo | Ej3 | 2.2.178 (including) | 2.2.178 (including) |